PRIVACY
Emailyze Privacy Policy
Do not make these dates dynamic. They are legal document revision dates, unlike the copyright year in your footer.
1. Introduction
Welcome to Emailyze.
This Privacy Policy explains how Emailyze ("Emailyze", "we", "us", or "our") collects, uses, stores, shares, protects, and otherwise processes personal data when you:
- visit our website;
- create or use an Emailyze account;
- use our public email verifier;
- verify individual email addresses;
- upload or process email lists;
- manage contacts and contact lists;
- create or send campaigns;
- use templates or AI-assisted features;
- configure sending or SMTP profiles;
- use our APIs;
- contact support; or
- otherwise interact with our services.
Our website, software, email verification services, APIs, campaign tools, contact management features, reporting features and related services are collectively referred to as the "Services."
Please read this Privacy Policy carefully.
2. Who We Are
The operator responsible for this Privacy Policy is:
Emailyze
Privacy contact:support@emailyze.email
If Emailyze has not yet been incorporated, do not identify it as a registered company until registration is complete.
3. The Different Roles Emailyze May Have
Our privacy role depends on how personal data enters the Services.
3.1 Data relating directly to our own users
For information such as:
- account registration details;
- billing information;
- support communications;
- website usage;
- public verifier usage;
- direct marketing preferences; and
- security information,
Emailyze generally determines why and how the data is used.
3.2 Customer Data processed through Emailyze
Customers may upload or submit information such as:
- email addresses;
- CSV files;
- contact lists;
- recipient data;
- campaign information; and
- other contact-related information.
For this Customer Data, the customer generally determines:
- which information is uploaded;
- why it is processed;
- whose information is processed;
- whether verification should occur;
- whether contacts should be added to a list; and
- whether campaigns should be sent.
In these situations, Emailyze generally processes the data to provide the Services requested by the customer.
The customer remains responsible for ensuring that its collection and use of Customer Data is lawful.
3.3 Important distinction
An email address being marked Valid or Deliverable does not mean the owner consented to receive marketing email.
Verification is a technical assessment.
It does not determine:
- marketing consent;
- lawful basis for contacting someone;
- whether a recipient has subscribed;
- whether a campaign is legally permitted; or
- whether the recipient wishes to receive the message.
Customers are responsible for those decisions.
4. Information We Collect
The information we collect depends on how you use Emailyze.
4.1 Account Information
When you create or manage an account, we may collect:
- name;
- email address;
- username;
- password or authentication information;
- account identifier;
- organisation or business name;
- profile information;
- account preferences;
- plan information; and
- account status.
Passwords should be stored using secure one-way password hashing and should never be stored in readable plain text.
Confirm this matches your authentication implementation before publishing.
4.2 Billing and Transaction Information
When you purchase a subscription, credits or another paid service, we may process:
- billing name;
- billing email;
- billing address;
- tax information;
- purchased plan or credit package;
- payment status;
- invoice details;
- transaction identifiers;
- payment date; and
- refund or dispute information.
Payment card or banking information may be collected directly by our payment processor rather than stored by Emailyze.
The final policy should identify your actual production payment processor once selected.
For example:
Payment provider: [INSERT ACTUAL PROVIDER]
Do not name a payment processor you are not actually using.
5. Email Verification Data
When you use an email verification feature, we may process:
- the submitted email address;
- email format and syntax information;
- domain information;
- DNS and mail server signals;
- mailbox-related technical signals;
- verification result;
- deliverability score;
- status;
- reason codes;
- disposable-email signals;
- role-address signals;
- accept-all signals;
- free-provider signals;
- MX information;
- timestamps; and
- associated account or request information.
Verification information may be used to:
- perform the requested verification;
- display results;
- maintain verification history;
- calculate account usage;
- support downloads and reporting;
- detect abuse;
- troubleshoot errors; and
- improve reliability.
The exact signals available may change as the verification service evolves.
6. Public Quick Email Verifier
Visitors may be able to verify a limited number of email addresses without creating an account.
When the public verifier is used, we may process:
- the submitted email address;
- verification result;
- IP address;
- request date and time;
- browser or device information;
- session information;
- cookies or similar identifiers where used;
- rate-limit information; and
- security or abuse-detection signals.
We use this information to:
- provide the requested verification;
- enforce free usage limits;
- prevent automated abuse;
- protect the Services;
- investigate suspicious activity;
- measure basic service usage; and
- maintain technical reliability.
Public verification limits may be applied using combinations of:
- IP address;
- browser;
- session;
- account state;
- device-related signals; or
- other anti-abuse mechanisms.
Important
Do not state that you use device fingerprinting, CAPTCHA, permanent cookies or specific tracking technology unless the product actually does so.
7. Bulk Verification and Uploaded Files
When you upload a CSV or other supported file, we may process:
- the file;
- email addresses in the file;
- row-level information you choose to include;
- file name;
- file size;
- upload date;
- processing status;
- verification results;
- progress information; and
- downloadable result files.
We process uploaded files to:
- perform the requested bulk operation;
- generate verification results;
- display progress;
- permit downloads;
- create contact lists when instructed;
- provide support; and
- maintain service security.
You should upload only information you are authorised to process.
Before publication, you need a real retention rule
Choose and implement one of these models:
Option A — Automatic deletion
Uploaded source files are automatically deleted within [X] days after processing.
Option B — Account-controlled retention
Uploaded files remain available until the customer deletes them or the applicable retention period expires.
Option C — Mixed approach
Source files are automatically deleted after [X] days, while verification results remain available in the customer's account until deleted or the account is closed.
I strongly recommend Option C for Emailyze.
Do not publish a retention period until Codex/backend logic actually enforces it.
8. Contact Lists and Imported Contacts
When you create or import contact lists, we may process:
- email addresses;
- names where provided;
- list names;
- list identifiers;
- source information;
- verification status;
- campaign association;
- creation and update timestamps; and
- other information selected by the customer.
Contacts may enter Emailyze through:
- verification results;
- direct imports;
- CSV uploads;
- APIs; or
- other integrations made available in the future.
Customers are responsible for ensuring that they are authorised to upload, store, verify and use contact information.
9. Campaign Information
If you use campaign functionality, we may process:
- campaign name;
- campaign content;
- subject lines;
- recipient lists;
- templates;
- sender information;
- scheduling information;
- sending status;
- campaign timestamps;
- campaign configuration;
- bounce information;
- delivery events;
- open events;
- click events;
- failure information; and
- other campaign-related analytics.
We process this information to:
- create and operate campaigns;
- perform sending instructions;
- display status;
- produce reports;
- investigate delivery problems;
- detect abuse; and
- provide support.
10. Email Tracking
Emailyze may provide campaign analytics such as:
- delivered;
- bounced;
- opened;
- clicked;
- failed; or
- similar events.
Depending on the feature and configuration, tracking may rely on:
- links containing tracking parameters;
- small tracking resources;
- sending-provider event data;
- mail server events; or
- other technical signals.
Email tracking is not perfectly reliable.
For example:
- privacy features may block or preload tracking resources;
- security scanners may open links automatically;
- images may be blocked;
- devices may report events differently; and
- third-party systems may provide incomplete information.
Customers are responsible for providing any notice or obtaining any permission required for their campaigns and tracking practices.
11. SMTP and Sending Profile Information
Where users configure their own email-sending infrastructure, we may process:
- SMTP host;
- port;
- username;
- encrypted or otherwise protected credentials;
- sender identity;
- sender email address;
- configuration settings;
- connection status; and
- related technical information.
We use this information to connect to the configured sending service and perform sending operations requested by the customer.
Critical production check
Before publishing the final policy, confirm:
- whether SMTP passwords are stored;
- how they are encrypted;
- who can access them;
- when they are deleted; and
- whether they are ever written to logs.
Never publish:
"SMTP credentials are encrypted and never accessible to anyone"
unless you have verified that architecture.
A safer production clause is:
We apply technical and organisational safeguards designed to protect stored authentication credentials. Access is restricted to the extent reasonably necessary to operate and secure the relevant functionality.
12. API Data
If you use the Emailyze API, we may process:
- API keys or token identifiers;
- API requests;
- timestamps;
- endpoint usage;
- response status;
- IP address;
- rate-limit information;
- usage totals;
- error data; and
- security signals.
We use API data to:
- authenticate requests;
- provide results;
- enforce plan and rate limits;
- calculate usage;
- troubleshoot problems;
- secure the platform; and
- investigate abuse.
Customers should not expose API keys publicly.
13. AI-Assisted Features
Emailyze may offer artificial intelligence features for:
- generating campaign content;
- creating or improving templates;
- suggesting subject lines;
- producing text; or
- assisting with other content tasks.
When you use these features, we may process:
- prompts;
- instructions;
- template content;
- generated outputs;
- feature usage;
- error information; and
- associated account information.
Some AI functionality may be provided by third-party service providers.
Before launch, identify the actual AI providers used in production and update the Service Providers section.
Do not submit:
- passwords;
- payment card information;
- highly sensitive personal data; or
- confidential information you are not authorised to process
into AI prompts.
14. Website and Technical Information
When you access Emailyze, we may automatically process information such as:
- IP address;
- browser type;
- operating system;
- device type;
- referring URL;
- pages viewed;
- feature interactions;
- access dates and times;
- session information;
- error logs;
- performance information; and
- security events.
We may use this information to:
- operate the website;
- maintain sessions;
- understand product usage;
- improve performance;
- diagnose errors;
- prevent fraud;
- enforce usage limits; and
- secure the Services.
15. Cookies and Similar Technologies
Emailyze may use cookies or similar technologies for purposes such as:
Essential functionality
- maintaining sessions;
- authenticating users;
- preserving preferences;
- securing accounts; and
- preventing abuse.
Analytics
Where enabled, we may use analytics technologies to understand:
- page visits;
- traffic sources;
- product interactions;
- technical performance; and
- general usage patterns.
Marketing technologies
If Emailyze later uses advertising, retargeting or marketing pixels, this Privacy Policy and any cookie-consent mechanism should be updated before those technologies are enabled.
Important
Do not copy a generic statement saying you use:
- Google Analytics;
- Meta Pixel;
- Hotjar;
- Microsoft Clarity; or
- any other named service
unless that tool actually exists on your production website.
16. Support and Communications
When you contact us, we may process:
- your name;
- email address;
- account information;
- message contents;
- attachments;
- support history; and
- technical information needed to investigate your request.
We use this information to:
- respond to requests;
- resolve technical problems;
- provide account support;
- prevent fraud; and
- improve our Services.
17. How We Use Personal Data
Depending on the context, we may use personal data to:
- provide the Services;
- create and administer accounts;
- verify email addresses;
- process bulk verification jobs;
- create and manage contact lists;
- operate campaigns;
- connect to configured sending infrastructure;
- provide reports and analytics;
- provide API access;
- deliver AI-assisted features;
- process purchases and billing;
- enforce limits;
- provide support;
- maintain technical performance;
- prevent fraud and abuse;
- investigate security incidents;
- enforce our agreements;
- comply with legal obligations;
- communicate service changes; and
- improve the Services.
We should not use Customer Data for unrelated purposes.
18. Legal Grounds for Processing
Where applicable law requires a legal ground for processing, the ground may depend on the situation.
It may include:
Contractual necessity
For example:
- providing an account;
- processing requested verifications;
- managing plans;
- providing API services; and
- delivering features purchased by the user.
Consent
Where consent is requested for a specific activity.
Legitimate interests
Where legally available, such interests may include:
- securing the platform;
- preventing fraud;
- improving reliability;
- understanding product usage; and
- protecting legal rights.
Legal obligations
Where processing is required to comply with applicable law.
For Customer Data, customers are responsible for identifying the legal basis applicable to their own collection and use of that data.
20. International Data Transfers
Emailyze and its service providers may process data in countries other than the country where the user or contact is located.
Where required, we will use mechanisms designed to support lawful international transfers.
Customers are responsible for evaluating any international-transfer obligations relating to Customer Data they submit to the Services.
Before launch
Document the actual countries where your:
- VPS;
- database;
- backup server;
- AI provider; and
- payment provider
process data.
Do not write "all data remains in India" unless that is genuinely true for every production service.
21. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to:
- provide the Services;
- maintain accounts;
- fulfil customer instructions;
- comply with legal obligations;
- resolve disputes;
- prevent fraud;
- enforce agreements; and
- maintain security.
Different categories may have different retention periods.
Recommended Emailyze retention table
Use this only after backend implementation matches it:
My recommendation:
| Data | Recommended policy |
|---|---|
| Account data | While account is active + defined legal retention period |
| Billing records | As legally required |
| Public verification requests | Short abuse/security period |
| Source CSV files | Auto-delete after 30 days |
| Verification results | Until user deletes or account closes |
| Contact lists | Until user deletes or account closes |
| Campaign records | Until user deletes or account closes |
| Security logs | 30–180 days depending on need |
| Deleted-account backups | Purged according to backup rotation |
Source upload files: 30 days
Public verifier email request data: maximum 30 days unless needed for abuse/security
Application logs: 90 days
Security logs: up to 180 days
Account data: until account deletion, subject to legal retention needs
Backups after deletion: remove through normal rotation within 30–90 days
But do not publish these numbers until your backend and backups enforce them.
22. Data Security
We use reasonable technical and organisational measures designed to protect information against:
- unauthorised access;
- loss;
- misuse;
- alteration;
- disclosure; and
- destruction.
Measures may include, where appropriate:
- access controls;
- authentication;
- network safeguards;
- encryption;
- credential protection;
- logging;
- backups;
- vulnerability management; and
- security monitoring.
No method of storage or transmission is completely secure.
Accordingly, we cannot guarantee absolute security.
23. Data Breaches and Security Incidents
If we become aware of a personal-data breach or security incident, we will investigate and take appropriate action.
Where required by applicable law, we may notify:
- affected customers;
- affected individuals;
- relevant authorities; or
- other appropriate parties.
Customers should promptly notify us if they believe their:
- account;
- API key;
- SMTP credentials; or
- other authentication information
has been compromised.
24. Your Privacy Rights
Your rights depend on applicable law and circumstances.
They may include rights to:
- request access to personal data;
- request correction;
- request deletion;
- withdraw consent where processing relies on consent;
- object to certain processing;
- request restriction;
- obtain information about processing;
- request data portability where applicable;
- nominate another person where applicable;
- raise a grievance; and
- complain to a competent authority.
We may need to verify your identity before fulfilling a request.
Some requests may be limited where information must be retained for:
- security;
- fraud prevention;
- legal compliance;
- dispute resolution; or
- other lawful reasons.
India's current framework includes the DPDP Act and final DPDP Rules, while the GDPR provides additional rights in situations where it applies.
25. Requests Relating to Customer-Uploaded Data
This distinction is very important for Emailyze.
Suppose:
- Company ABC uploads someone's email address into Emailyze; and
- that person asks Emailyze to delete it.
Where Emailyze processes the information on behalf of Company ABC, the relevant customer may be responsible for handling the request.
Accordingly, if your request concerns information uploaded by an Emailyze customer, we may:
- identify the relevant customer where legally permitted;
- direct you to that customer; or
- assist the customer with the request.
We will not independently use Customer Data to decide who should receive campaigns.
26. Account Deletion
Users may request account deletion through:
[INSERT ACCOUNT DELETION METHOD]
For example:
- account settings;
- support request; or
- privacy@emailyze.email.
Following account deletion:
- active account access may be disabled;
- Customer Data may be scheduled for deletion;
- some information may remain temporarily in backups;
- legal or billing records may be retained where required; and
- information required for security or dispute resolution may be retained where lawful.
Important
Add an actual self-service delete-account feature if practical.
Do not promise immediate irreversible deletion if your database backups retain data for a period.
27. Marketing Communications
We may send marketing communications where legally permitted.
Users may opt out by:
- using an unsubscribe link;
- changing available communication settings; or
- contacting us.
Opting out of marketing does not stop essential service communications, such as:
- security notifications;
- billing messages;
- account notices; or
- important service updates.
28. Children's Privacy
Emailyze is designed for business and professional use and is not intended for children.
Users must be at least 18 years old, or the age of legal majority applicable to their use of the Services.
We do not knowingly seek to collect personal data directly from children through account registration.
If you believe a child has provided personal information directly to Emailyze improperly, contact us.
29. Do Not Sell Personal Data
Emailyze does not sell Customer Data or account personal data to advertisers.
We also do not allow advertisers to access customer conversations or private Customer Data merely because advertising or marketing services exist elsewhere.
If our practices change, this Privacy Policy will be updated before such changes are implemented where required.
30. Automated Analysis and Verification Decisions
Emailyze uses automated technical processing to generate:
- scores;
- verification statuses;
- risk classifications;
- reason codes; and
- other results.
These results assist users in evaluating email quality.
They:
- are based on available technical signals;
- may be incomplete;
- can change over time; and
- should not be treated as determinations about a person's character, creditworthiness, employment, legal rights or identity.
Emailyze verification results should not be used to make decisions with significant legal or similarly serious effects about individuals.
31. Third-Party Links
Our website may contain links to third-party websites or services.
We do not control the privacy practices of independent third parties.
You should review their policies before providing personal data.
32. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
- product changes;
- new features;
- legal requirements;
- new service providers;
- security developments; or
- operational changes.
The updated version will show a revised Last Updated date.
Where required or appropriate, we may provide additional notice of material changes.
33. Contact and Privacy Requests
For privacy questions or requests, contact:
Emailyzesupport@emailyze.email